SQLÈßÓà×ֶεIJßÂԺ͹ÜÀí
SQLÈßÓà×ֶεIJßÂԺ͹ÜÀí
http://www.examda.com/ncre/three/db/fudao/20091203/093528816.html
ÈßÓà×ֶεÄʹÓÃÔÚ¶à±íÁªºÏ²éѯ¶¼ÊÇ´óÊý¾ÝÁ¿µÄ±íµÄÇé¿öÏ£¬È·ÊµÊǸö²»´íµÄÑ¡Ôñ£¬ÓÐЧµÄ¼õÉÙÁËIO²Ù×÷¡£µ«½áºÏÒÑÓеÄÏîÄ¿²úÆ·À´¿´£¬ÈßÓà×Ö¶ÎȷʵÊÇË«Èн£¡£ÓÈÆäÊÇ´óÏîÄ¿µÄ¿ª·¢£¬Èç¹ûºöÂÔij¸ö±íµÄÈßÓà×ֶεĸüУ¬ÄÇôºó¹ûÊÇÔÖÄÑÐԵġ£ÈçºÎÓÐЧµÄ¹ÜÀíÈßÓà×Ö¶ÎÊÇ¿ª·¢×éÄÚ±ØÐë½â¾öµÄÎÊÌâ¡£ÎҵĽâ¾ö·½°¸ÊÇ£ºÊ¹ÓÃרÃŵıíÀ´¹ÜÀíÈßÓà×ֶΡ£ÀýÈçarticle±íÓÐÒÔÏÂÈßÓà×Ö¶Î
¡¡¡¡fromUserName,toUserName
¡¡¡¡ÈçºÎ¹ÜÀíÕâÁ½¸ö×Ö¶ÎÄØ£¿Í¨¹ý½¨Á¢Ò»¸ö±í£¬±í½á¹¹ÈçÏÂ
¡¡¡¡id,objTable,objName,sourceTable, sourceId,level£¬isUpdate
¡¡¡¡ÆäÖÐobjTable=Ä¿±ê±í£¬objName= Ä¿±ê×ֶΣ¬sourceTable=Ô´±í,sourceId=Ô´±íID,level=ÊÇ·ñÐèÒªÁ¢¼´¸üÐÂ,isUpdate=ÊÇ·ñÒѸüÐÂ
¡¡¡¡ÆäÖУ¬level×ֶκÜÓбØÒª£¬ÓÐЩÈßÓà×ֶβ¢²»ÐèÒªÔÚÔ´±íÐ޸ĺóÁ¢¼´¸üУ¬ÄÇô¿ÉÒÔͨ¹ýÒ»¸ö¶¨ÆÚ¸üвßÂÔÀ´¸üС£
¡¡¡¡Í¨¹ý¿â±íµÄ¹ÜÀí£¬ÅäºÏÒ»¸öºÏÀíµÄ´æ´¢¹ý³Ì£¬ÈßÓà×ֶεÄʹÓý«²»ÔÙÊÇÄÑÌâ¡£
¡¡¡¡¾ÙÀý£¬Èç¹ûÉÏÃæÁ½¸ö×ֶη¢Éú±ä»¯£¬ÔòʹÓô¥·¢Æ÷»òÕßµ÷ÓÃÕâ¸ö´æ´¢¹ý³ÌÀ´¼ì²éÊÇ·ñÓÐÐèÒªÁ¢¼´¸üеÄÈßÓà×ֶΣ¬ÐèÒªÔòÁ¢¼´¸üУ¬²»ÐèÒªÔòisUpdateÖÃ0,µÈµ½ÖÜÆÚÐԵIJßÂÔÀ´¸üÐÂͬʱisUpdate=1¡£
¡¡¡¡Èç¹ûÏîÄ¿ÖÐʹÓÃÁËmemcache,Ôò»¹¿ÉÒÔʹÓÃÁíÒ»¸ö˼·À´½øÒ»²½¼õСÊý¾Ý¿âIO²Ù×÷¡£ÏÂÆªÔÙÕ¹¿ªÀ´Ëµ¡£
Ïà¹ØÎĵµ£º
Oracleµ÷ÕûÓëSQL Óï¾äµÄµ÷ÓŵĹØÏµ
ÔÚOracleµ÷ÕûÖÐÎÒÃÇ»¹»áÉæ¼°µ½SQL Óï¾äµÄµ÷ÓÅ£¬ÎÒÃǽÓÏÂÀ´¾ÍÀ´¿´ÒÔÏ嵀 SQL Óï¾äµÄµ÷ÓÅ¡£ÎÒÃǶ¼ÖªµÀ Oracle ÖÐµÄ SQL µ÷ÓÅÊÇÒ»¸öÏ൱¸´ÔÓµÄÖ÷Ì⣬ÉõÖÁÊÇÐèÒªÕû±¾ÊéÀ´½éÉÜ Oracle SQL µ÷ÓŵÄϸ΢²î±ð¡£
²»¹ýÓÐһЩ»ù±¾µÄ¹æÔòÊÇÿ¸ö Oracle DBA ¶¼ÐèÒª¸ú´ÓµÄ£¬ÕâЩ¹æÔò¿ÉÒÔ¸ÄÉÆËûÃÇϵͳµÄ ......
SQL×¢Èë¹¥»÷µÄΣº¦ÐԺܴó¡£ÔÚ½²½âÆä·ÀÖ¹°ì·¨Ö®Ç°£¬Êý¾Ý¿â¹ÜÀíÔ±ÓбØÒªÏÈÁ˽âÒ»ÏÂÆä¹¥»÷µÄÔÀí¡£ÕâÓÐÀûÓÚ¹ÜÀíÔ±²ÉÈ¡ÓÐÕë¶ÔÐԵķÀÖδëÊ©¡£
¡¡¡¡Ò»¡¢ SQL×¢Èë¹¥»÷µÄ¼òµ¥Ê¾Àý¡£
¡¡¡¡statement := "SELECT * from Users WHERE Value= " + a_variable + "
¡¡¡¡ÉÏÃæÕâÌõÓï¾äÊÇºÜÆÕͨµÄÒ»ÌõSQLÓï¾ä£¬ËûÖ÷ҪʵÏֵŦÄܾÍÊÇÈÃÓû§Ê ......
±£»¤SQL ServerÊý¾Ý¿âµÄÊ®´ó¾øÕÐ
http://blog.csdn.net/cncco/archive/2007/09/15/1785880.aspx
1. °²×°×îеķþÎñ°ü
ΪÁËÌá¸ß·þÎñÆ÷°²È«ÐÔ£¬×îÓÐЧµÄÒ»¸ö·½·¨¾ÍÊÇÉý¼¶µ½SQL Server 2000 Service Pack 3a (SP3a)¡£ÁíÍ⣬Äú»¹Ó¦¸Ã°²×°ËùÓÐÒÑ·¢²¼µÄ°²È«¸üС£
2. ʹÓÃMicrosoft»ùÏß°²È«ÐÔ·ÖÎöÆ÷£¨MBSA£©À´ÆÀ¹À·þÎñÆ÷µÄ°² ......
½â¾öSQL Injection©¶´µÄÒ»¸öº¯Êý
http://blog.csdn.net/cncco/archive/2006/04/07/654254.aspx
º¯Êý
<%
Function CheckInput(str,strType)
'º¯Êý¹¦ÄÜ£º¹ýÂË×Ö·û²ÎÊýÖеĵ¥ÒýºÅ£¬¶ÔÓÚÊý×Ö²ÎÊý½øÐÐÅжϣ¬Èç¹û²»ÊÇÊýÖµÀàÐÍ£¬Ôò¸³Öµ0
'²ÎÊýÒâÒ壺 str ......